CVE-2021-4471 Details
Description
TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker can enumerate and download files within the directory to obtain valid account usernames and passwords, leading to loss of confidentiality and further unauthorized access.
A vulnerability in TG8 Firewall allows remote unauthenticated attackers to access a directory over HTTP that contains credential files for previously logged-in users. This directory, which is exposed without authentication, can be accessed to enumerate and download files, thereby obtaining valid usernames and passwords. The vulnerability leads to unauthorized access by disclosing sensitive information that could be exploited to gain further access to user accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 14, 2025CISA-ADP
Assessed Nov 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/ | CISA-ADP | BundleExploitTechnical Analysis |
| https://ssd-disclosure.com/ssd-advisory-tg8-firewall-preauth-rce-and-password-disclosure/ | [email protected] | BundleExploitTechnical Analysis |
| https://web.archive.org/web/20211024224240/http://www.tg8security.com/ | [email protected] | Vendor |
| https://www.vulncheck.com/advisories/tg8-firewall-unauthenticated-user-password-disclosure | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TG8 Firewall | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | CVE Modified | CISA-ADP |
| Nov 14, 2025 | New CVE Received | [email protected] |
Volerion